CVE-2014-9148 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 11.4% (pctl 96)
Patch early
A public exploit exists.
Description
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 11.45% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-10-16 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| fiyo | fiyo cms |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | 2015-03-31 |
References
- http://packetstormsecurity.com/files/131165/FiyoCMS-2.0.1.8-XSS-SQL-Injection-URL-Bypass.html
- http://www.securityfocus.com/bid/73437
- https://www.exploit-db.com/exploits/36581/
- http://packetstormsecurity.com/files/131165/FiyoCMS-2.0.1.8-XSS-SQL-Injection-URL-Bypass.html
- http://www.securityfocus.com/bid/73437
- https://www.exploit-db.com/exploits/36581/
→ the Explorer · watch your stack · NVD